Deployment Architecture

Universal forwarder connecting to heavy forwarder but not sending windows event logs

jgorman_THG
Explorer

Hello,

I have a client with a Windows 2008r2 server running a universal forwarder and set to forward Windows Event, Application, and Security logs to a heavy forwarder. From there the client is using SplunkCloud.

In SplunkCloud, I can see the machine connecting, but it doesn't seem to be sending any information.

I can see the following information:

08-23-2016 01:24:27.191 +0000 INFO Metrics - group=per_host_thruput, series="Machine_Name", kbps=0.031723, eps=0.387102, kb=0.983398, ev=12, avg_age=0.916667, max_age=1
host = idx1.client.splunkcloud.com source = /opt/splunk/var/log/splunk/metrics.log sourcetype = splunkd

The client does not believe it is a GPO problem.

I do not have direct access to the machine But I will be asking the client for the input.conf and output.conf files tomorrow.

Can someone point me in the right direction for solving this problem?

Thanks,

0 Karma

jgorman_THG
Explorer

HI Guys!

Thanks for you input. It was a stupid simple mistake, my colleague who set the system-up didn't create a "wineventlog" index, and me being a newby didn't know to look for it.

Thanks for your input!

0 Karma

sk314
Builder

Could it be a timestamp issue? Did you try searching over all-time to see if you see any results. This might sound silly...but It has happened many times.

0 Karma

rharrisssi
Path Finder

I think we need to first see inputs.conf and outputs.conf and go from there. Instead of asking the client for specific files, ask for the entire etc directory in the UF in-case we have more questions.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...